Offering: HULK hulk inclusion category: bugfix bugzilla: https://atomgit.com/src-openeuler/kernel/issues/15950 CVE: CVE-2026-53264 -------------------------------- Add struct tc_action_rcu to fix kabi breakage of struct tc_action. Fixes: 5057e1aca011 ("net/sched: act_api: use RCU with deferred freeing for action lifecycle") Signed-off-by: Dong Chenchen <dongchenchen2@huawei.com> --- include/net/act_api.h | 8 +++++++- net/sched/act_api.c | 21 ++++++++++++++++++++- 2 files changed, 27 insertions(+), 2 deletions(-) diff --git a/include/net/act_api.h b/include/net/act_api.h index 56f49351fd51..93935a2e0b0f 100644 --- a/include/net/act_api.h +++ b/include/net/act_api.h @@ -20,6 +20,7 @@ struct tcf_idrinfo { }; struct tc_action_ops; +struct tc_action_rcu; struct tc_action { const struct tc_action_ops *ops; @@ -31,6 +32,7 @@ struct tc_action { atomic_t tcfa_bindcnt; int tcfa_action; struct tcf_t tcfa_tm; + KABI_FILL_HOLE(struct tc_action_rcu *tcfa_rcu) struct gnet_stats_basic_sync tcfa_bstats; struct gnet_stats_basic_sync tcfa_bstats_hw; struct gnet_stats_queue tcfa_qstats; @@ -42,7 +44,6 @@ struct tc_action { struct tc_cookie __rcu *user_cookie; struct tcf_chain __rcu *goto_chain; u32 tcfa_flags; - struct rcu_head tcfa_rcu; u8 hw_stats; u8 used_hw_stats; bool used_hw_stats_valid; @@ -58,6 +59,11 @@ struct tc_action { #define tcf_rate_est common.tcfa_rate_est #define tcf_lock common.tcfa_lock +struct tc_action_rcu { + struct tc_action *action; + struct rcu_head rcu; +}; + #define TCA_ACT_HW_STATS_ANY (TCA_ACT_HW_STATS_IMMEDIATE | \ TCA_ACT_HW_STATS_DELAYED) diff --git a/net/sched/act_api.c b/net/sched/act_api.c index bed04ae3003c..b29d1f34a6d4 100644 --- a/net/sched/act_api.c +++ b/net/sched/act_api.c @@ -112,9 +112,18 @@ struct tcf_chain *tcf_action_set_ctrlact(struct tc_action *a, int action, } EXPORT_SYMBOL(tcf_action_set_ctrlact); +static void tc_action_free_rcu(struct rcu_head *p) +{ + struct tc_action_rcu *ta = container_of(p, struct tc_action_rcu, rcu); + + kfree(ta->action); + kfree(ta); +} + static void free_tcf(struct tc_action *p) { struct tcf_chain *chain = rcu_dereference_protected(p->goto_chain, 1); + struct tc_action_rcu *ta = p->tcfa_rcu; free_percpu(p->cpu_bstats); free_percpu(p->cpu_bstats_hw); @@ -124,7 +133,7 @@ static void free_tcf(struct tc_action *p) if (chain) tcf_chain_put_by_act(chain); - kfree_rcu(p, tcfa_rcu); + call_rcu(&ta->rcu, tc_action_free_rcu); } static void offload_action_hw_count_set(struct tc_action *act, @@ -731,10 +740,16 @@ int tcf_idr_create(struct tc_action_net *tn, u32 index, struct nlattr *est, { struct tc_action *p = kzalloc(ops->size, GFP_KERNEL); struct tcf_idrinfo *idrinfo = tn->idrinfo; + struct tc_action_rcu *ta; int err = -ENOMEM; if (unlikely(!p)) return -ENOMEM; + + ta = kzalloc(sizeof(*ta), GFP_KERNEL); + if (unlikely(!ta)) + goto err0; + refcount_set(&p->tcfa_refcnt, 1); if (bind) atomic_set(&p->tcfa_bindcnt, 1); @@ -758,6 +773,8 @@ int tcf_idr_create(struct tc_action_net *tn, u32 index, struct nlattr *est, p->tcfa_tm.lastuse = jiffies; p->tcfa_tm.firstuse = 0; p->tcfa_flags = flags; + p->tcfa_rcu = ta; + ta->action = p; if (est) { err = gen_new_estimator(&p->tcfa_bstats, p->cpu_bstats, &p->tcfa_rate_est, @@ -778,6 +795,8 @@ int tcf_idr_create(struct tc_action_net *tn, u32 index, struct nlattr *est, err2: free_percpu(p->cpu_bstats); err1: + kfree(ta); +err0: kfree(p); return err; } -- 2.25.1